Harvest Now, Decrypt Later: Why Quantum Risk Starts Today
Attackers can copy encrypted data today and wait for a quantum computer to read it. Here is how the threat works, what it does and does not affect, and how to judge whether your data is exposed.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
Most security threats need an attacker to act at the moment of the attack. This one does not. An attacker can record encrypted traffic or copy encrypted files today, store them cheaply, and decrypt them years later once a powerful enough quantum computer exists. Security agencies call this “harvest now, decrypt later”. You may also see it called “store now, decrypt later”.
NIST describes it as one of the main reasons the move to post-quantum cryptography is urgent.1 The US Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency and NIST named it in their joint 2023 quantum readiness factsheet,2 and a US executive order signed in June 2026 cites the same risk of adversaries collecting information now to decrypt once large quantum computers work.3 This article explains how the attack works, which data it touches, and how to tell whether yours is in scope.
How The Attack Works
- Data Is Protected With Today’s Public-Key Cryptography
A TLS session, VPN tunnel or encrypted email uses a key that was agreed with RSA, Diffie-Hellman or elliptic curve cryptography.
- An Attacker Records The Encrypted Data
Nothing is decrypted yet. The attacker only needs a copy of the traffic, including the handshake where the key was agreed.
- The Data Sits In Storage For Years
Storage is cheap, so the attacker can keep large volumes of material and wait.
- A Quantum Computer Breaks The Key Exchange
Once a cryptographically relevant quantum computer exists, the recorded key agreement is solved, the session key is recovered and the data is read.
The attack works because of how secure connections are built. As the public-key cryptography article explains, a connection first uses a public-key algorithm to agree a session key, then uses a symmetric cipher such as AES with that key to protect the data. The symmetric cipher is not the weak point. The public-key step that produced its key is, because Shor’s algorithm can solve the underlying factoring or discrete logarithm problem.4
NIST’s draft transition guidance makes this link directly. Because the session keys agreed during key establishment protect confidentiality, the harvest risk has to shape the migration timeline for key establishment. NIST applies the same reasoning to email: like any encryption that keeps data confidential, S/MIME email encryption is exposed.1
What It Does Not Affect
Harvesting is a threat to confidentiality. It is not a threat to digital signatures in the same way. A forged signature only helps an attacker if they can produce it while the signature still matters, which requires a working quantum computer at the time of the attack. NIST states this explicitly: unlike encryption, an authentication system stays secure as long as its algorithms and keys are secure when the authentication happens.1 A login or handshake that finished years ago cannot be forged after the event.
That does not make signatures a later problem. Some signing keys live for a very long time, such as certificate authority roots and the keys that devices use to check firmware updates. NIST notes that where a device’s verification code cannot be updated after manufacture, the device should be designed to require quantum-resistant signatures if it may still be in service when a quantum computer arrives.1 Signatures that must keep being trusted for years, such as on contracts, archived records or software, raise a related concern. Once a signing key can be broken, an attacker could create new forgeries under it, possibly carrying an earlier date. A date written by the signer proves nothing on its own, which is why NIST recommends independent evidence such as a timestamp from a trusted authority,5 and signatures checked after that point need evidence that does not rest on the old algorithm alone. The urgency for signatures comes from long lifetimes and replacement cycles, not from harvesting.
Judging Whether Your Data Is Exposed
The deciding question is simple: will this data still need to be secret when a cryptographically relevant quantum computer exists? Nobody knows that date. The Q-Day and Mosca’s inequality article gives a structured way to reason about it, including a calculator. The flowchart below is a quicker first pass for a single data flow.
Does the data cross a network or sit somewhere an attacker could copy it?
- Yes:
Is its encryption key agreed or wrapped with RSA, Diffie-Hellman or elliptic curve cryptography?
- Yes:
Must the data stay confidential for more than about ten years?
- Yes:
Exposed Now Prioritise this flow for post-quantum key exchange.
- No:
Exposure Depends On Timelines Use Mosca’s inequality with a range of estimates to decide when to migrate.
- Yes:
- No:
Check The Key Path Pre-shared symmetric keys or post-quantum key exchange are not exposed in the same way. Confirm how keys are distributed.
- Yes:
- No:
Low Harvest Exposure Harvesting needs a copy of the ciphertext. Keep reviewing as systems change.
The ten-year threshold in the last question is a prompt, not a standard. It reflects the expert survey figures discussed in the Q-Day article, which put a meaningful chance on a capable quantum computer arriving within a decade. NIST’s own summary is that even if quantum computers are a decade away, organisations need to start migrating now to avoid exposing encrypted data, and it singles out data with long-term sensitivity such as government secrets and medical records.1
Which Data Matters Most
The most exposed data must stay secret for a long time and travels over networks or sits where attackers can copy it. Health and financial records, intellectual property, government and defence information, identity data and long-term contracts are typical examples. Short-lived data, such as a one-time code that expires in a minute, is far less exposed.
The CISA, NSA and NIST factsheet frames the threat around data that needs long-term confidentiality protection.2 In practice, that means the question to ask of each system is how long its data stays sensitive, not how much of it there is.
Where To Start
The first step in almost every government roadmap is to find out where and how your organisation uses cryptography. The CISA, NSA and NIST factsheet recommends a quantum readiness roadmap, a cryptographic inventory, an assessment of supply chain dependencies and early conversations with vendors.2 With an inventory in hand you can rank data flows by how long their contents must stay secret and move the most exposed ones to post-quantum key exchange first. The Preparing For Migration group covers that work, and What Governments Expect summarises the deadlines.
Footnotes
-
NIST, IR 8547 (initial public draft), “Transition to Post-Quantum Cryptography Standards”, November 2024. nvlpubs.nist.gov ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
CISA, NSA and NIST, “Quantum-Readiness: Migration to Post-Quantum Cryptography”, 21 August 2023. cisa.gov ↩ ↩2 ↩3
-
The White House, Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks”, 22 June 2026. govinfo.gov ↩
-
P. W. Shor, “Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer”, arXiv quant-ph/9508027, submitted 30 August 1995. arxiv.org ↩
-
NIST, SP 800-102, “Recommendation for Digital Signature Timeliness”, September 2009. nist.gov ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.